Improper Authentication in team-alembic AshAuthentication
CVE-2026-80218

7.6HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-80218?

The AshAuthentication framework in team-alembic is vulnerable to improper authentication, allowing attackers with access to a sign-in token for one authenticated resource to potentially gain unauthorized access to a user account in a different resource. This flaw arises from the way in which the JWT token's subject claim is parsed, specifically when the URI's path segment is disregarded. As a result, the system wrongly associates the sign-in token with various resources which share identical primary-key field names. It is important for developers to be aware of this vulnerability and implement necessary patches to safeguard user authentication.

Affected Version(s)

ash_authentication 3.10.5 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication eca8cadea0f1595ed2c10a0c177b1da9aa9e5269

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.